1.2.5 Two-factor authentication with the SSH server

Information

Two-factor authentication provides an additional level of security by requiring administrators to perform X.509 certificate-based authentication with the AOS-CX SSH server. The two factors are possession of the certificate private key and knowledge of the password associated with the certificate private key.

The switch must be configured with the corresponding CA certificate which issued the administrator's certificate.

Customers with a large number of administrators can be configuration and maintenance challenge across a large network. Use of certificate-based and two-factor authentication can simplify this maintenance for customers.

Solution

switch(config)# ssh certificate-as-authorized-key
switch(config)# ssh two-factor-authentication authorization local

Impact:

Any changes in administrator user passwords or the additional or removal of administrator accounts can become a maintenance headache for customers. Use of two-factor authentication only requires the enablement of the feature and the addition of the corresponding CA certificate as a trust anchor.

See Also

https://workbench.cisecurity.org/benchmarks/24202